Per OWASP DSOMM Build and Deployment + Infrastructure Hardening dimensions: secure the build + deployment + infrastructure stack. Requirements include (a) implement signed builds + artefact integrity + secure pipeline configuration + (b) operate vulnerability gating policies + environment promotion controls + (c) scan infrastructure-as-code + configuration-as-code + container images + (d) implement container + orchestration security including image scanning + runtime protection + admission control + (e) operate cloud security posture management + environment isolation + access controls + (f) implement secrets management including dedicated secret store + rotation + no hard-coded secrets + (g) implement configuration hardening baselines + drift detection + remediation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.